Monday, April 27, 2026
HomeUncategorized

Uncategorized

WinRAR 0-Day Exploit Hits Dark Web Market at $80K

WinRAR, the ubiquitous Windows file-archiving utility installed on hundreds of millions of systems worldwide, is once again in the cross-hairs of cybercriminals. A threat actor using the moniker “zeroplayer” has surfaced on a prominent dark-web marketplace, advertising what they claim is a previously unknown...

UK Police Arrest Four Hackers Over Cyber Attacks on M&S, Co-op, and Harrods

UK authorities have made significant progress in their investigation into cyber attacks targeting major British retailers, with four suspects now in custody following coordinated arrests across the West Midlands and London. The National Crime Agency (NCA) arrested two males aged 19, a 17-year-old male,...

ServiceNow Vulnerability Exposed Sensitive Data to Attackers

A newly disclosed high-severity vulnerability in ServiceNow’s cloud platform, dubbed Count(er) Strike, could have allowed malicious actors to exfiltrate personally identifiable information, credentials, and other proprietary data from hundreds of tables with minimal access. Discovered by Varonis Threat Labs in February 2024 and formally...

Brave Browser Launches Official Android Version on F-Droid

Brave Software has announced a significant development for privacy-conscious Android users by making its browser available through a dedicated F-Droid repository. This strategic move offers users an alternative installation method that bypasses Google Play Store, addressing growing concerns about Big Tech's control over app...

CISA Warns: ValveLink Vulnerabilities Allow Unauthorized Access to Sensitive Data

The Cybersecurity and Infrastructure Security Agency (CISA) has issued a critical security advisory warning about multiple severe vulnerabilities in Emerson ValveLink Products that could allow attackers to access industrial control systems and read sensitive information stored in cleartext memory. Released on July 8, 2025,...

GitLab Vulnerabilities Allow Remote Code Execution via Malicious Content Injection

GitLab has released critical security patches addressing multiple vulnerabilities, including a high-severity cross-site scripting (XSS) vulnerability that could allow attackers to execute malicious actions on behalf of users. The company issued versions 18.1.2, 18.0.4, and 17.11.6 for both Community Edition (CE) and Enterprise Edition...